note 33277 added to function.strip-tags
| From: | ( www.notforidiots.com ) | Date: | Fri, 20 Jun 2003 16:37:38 +0000 |
| Subject: | note 33277 added to function.strip-tags | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-50762@lists.php.net to get a copy of this message | ||
To fix the <scr<script></script>ipt> bug, I'm going to use the following
function for my upcoming forum project:
function realsafehtml($str) {
// Don't do anything if there's no difference or if the original string is empty
$oldstr = "";
while($str != $oldstr) // Loop until it got no more effect
{
$oldstr = $str;
//nuke script and header tags and anything inbetween
$str = preg_replace("'<script[^>]*?>.*?</script>'si",
"", $str);
$str = preg_replace("'<head[^>]*?>.*?</head>'si",
"", $str);
//listed of tags that will not be striped but whose attributes will be
$allowed = "br|b|i|p|u|a|center|hr";
//start nuking those suckers. don you just love MS Word's HTML?
$str = preg_replace("/<((?!\/?($allowed)\b)[^>]*>)/xis", "",
$str);
$str = preg_replace("/<($allowed).*?>/i", "<\\1>", $str);
}
return $str;
}
It's obviously more expensive than the original function, but also a lot more secure :) I hope
this can help someone - didn't test it much yet, though.
----
Manual Page -- http://www.php.net/manual/en/function.strip-tags.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+33277
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+33277&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+33277&report=yes